CVE-2025-54123 is a command injection vulnerability in Hoverfly affecting version 1.11.3 and earlier. The issue is present in the middleware management API endpoint /api/v2/hoverfly/middleware, where user-supplied input is insufficiently validated and sanitized before being used by middleware execution logic. According to the provided content, the flaw results from a combination of code-level issues: insufficient input validation in middleware.go (lines 94-96), unsafe command execution in local_middleware.go (lines 14-19), and immediate execution during testing in hoverfly_service.go (line 173). An attacker can supply malicious middleware configuration or payloads that are passed to system commands, leading to arbitrary command execution on the host running Hoverfly.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/api/v2/hoverfly/middleware endpoint and the set middleware API. Limit exposure of the Hoverfly management interface to trusted administrative networks only, require authentication, and avoid exposing the management API to untrusted users or the public Internet. Additional compensating controls include network ACLs, reverse-proxy allowlisting, and monitoring for suspicious middleware configuration changes or command execution behavior.Patch, then assume compromise.
17e60a9bc78826deb4b782dca1c1abd3dbe60d40, included in version 1.12.0, disables the set middleware API by default. Review deployment configuration and documentation changes associated with this release to ensure the middleware management API is not unnecessarily exposed or re-enabled without appropriate safeguards.7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small Python exploit PoC for CVE-2025-54123 targeting SpectoLabs Hoverfly. It contains two standalone scripts: CVE-2025-54123.py and test.py. Both follow the same structure: define hardcoded target parameters and credentials, authenticate to the Hoverfly API at /api/token-auth, extract a bearer token, then send a PUT request to /api/v2/hoverfly/middleware with a JSON body specifying '/bin/bash' as the binary and attacker-controlled shell content in the 'script' field. The main exploit script executes a simple 'id' command and parses the API error response to recover stdout, demonstrating authenticated RCE. The second script is effectively a payload variant that swaps the command for a base64-encoded bash reverse shell connecting back to 10.10.14.119:1234. Although argparse options are declared in the main script, the parsed target, port, credentials, token, and command are not actually wired into the request variables, so the exploit currently relies on hardcoded values (devarea.htb:8888, admin / O7IJ27MyyXiU). Overall, this is a real exploit PoC rather than a detector: its core capability is authenticated remote shell command execution through the Hoverfly middleware API, with one script demonstrating command execution and the other demonstrating post-exploitation shell access.
This repository is a small standalone Python exploit for CVE-2025-54123, an authenticated remote code execution issue in SpectoLabs Hoverfly <= 1.11.3. The repo contains three files: a detailed README, the main exploit script (exploit.py), and a minimal requirements.txt. The exploit is not part of a larger framework. The Python script is a polished CLI tool that uses requests, urllib3, and rich for HTTP interaction and terminal output. It defines constants for the target product and vulnerable endpoints, normalizes the supplied base URL, optionally configures a local proxy at 127.0.0.1:8080, authenticates against /api/token-auth, and then abuses /api/v2/hoverfly/middleware to trigger command execution. Based on the README and visible code structure, the exploit extracts command output from Hoverfly error responses, enabling direct output retrieval after execution. Primary capabilities include: check-only mode to validate reachability/authentication, single arbitrary command execution, an interactive pseudo-shell loop, and reverse shell payload delivery. The reverse shell mode appears to generate a shell one-liner from attacker-supplied LHOST:LPORT values and dispatch it through the same command injection path. This makes the exploit operational rather than a simple detection script or bare PoC. Fingerprintable targets and endpoints are centered on the Hoverfly admin API: /api/token-auth for login and /api/v2/hoverfly/middleware for exploitation, typically on port 8888. The code also supports optional traffic routing through a local proxy at http://127.0.0.1:8080. The README includes example callback and command targets such as 10.0.0.1:4444 and /etc/passwd, but these are illustrative rather than hardcoded operational infrastructure. Overall, the repository’s purpose is to provide an authenticated RCE exploit against vulnerable Hoverfly deployments by abusing unsafe middleware execution. Successful exploitation yields arbitrary command execution as the Hoverfly service user and may provide direct command output or a reverse shell depending on operator choice.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-54123 affecting Hoverfly. It contains two files: a single executable Python script (CVE-2025-54123.py) and a README with usage examples. The script is the clear entry point and implements the full exploit flow. Operationally, the exploit performs authenticated RCE. It first creates a requests session and POSTs credentials to /api/token-auth to retrieve an access token (accepting either access_token or token in the JSON response). If authentication succeeds, it sends an authenticated PUT request to /api/v2/hoverfly/middleware with JSON fields binary set to /bin/bash and script set to either a user-supplied command or a generated bash reverse shell one-liner. This indicates the exploit abuses Hoverfly middleware configuration to cause server-side execution of arbitrary shell commands. Capabilities include: (1) direct command execution via the -c option, and (2) reverse shell delivery via the -r LHOST LPORT option. The reverse shell payload uses bash's /dev/tcp mechanism to connect back to an attacker listener. The script prints token information, reports the target endpoints used, and attempts rudimentary output parsing from the HTTP response. Its output handling appears imperfect or partially hardcoded (it prints a fixed string dev_ryan when STDOUT is found), but that does not change the core exploit behavior. The exploit is not part of a larger framework such as Metasploit or Nuclei. It is a standalone Python script using argparse and requests. Because it includes an actual execution payload and reverse shell support, it is more than a basic detection script or documentation-only PoC; however, it remains relatively simple and hardcoded, so OPERATIONAL is the best maturity fit rather than WEAPONIZED.
This repository is a small standalone Bash proof-of-concept exploit for CVE-2025-54123, an authenticated command injection / RCE issue in Hoverfly middleware. The repository contains three files: a single executable exploit script (CVE-2025-54123.sh), a README with usage and vulnerability context, and an MIT license. The exploit is not part of a larger framework. The main script performs a straightforward exploitation chain: it validates that the supplied target base URL is reachable, authenticates to the Hoverfly API using POST /api/token-auth with provided username and password, extracts a bearer token from the JSON response, queries GET /api/v2/hoverfly/version to identify the installed version, compares that version against a hardcoded vulnerable list, and then sends a PUT request to /api/v2/hoverfly/middleware with JSON containing binary set to /bin/bash and script set to an operator-supplied command. The script then parses the response to display STDOUT from the executed command. Primary capability: authenticated remote OS command execution on vulnerable Hoverfly instances. This can be used to run arbitrary shell commands with the privileges of the Hoverfly process. The exploit does not include persistence, lateral movement, or post-exploitation automation; it is a direct command-execution PoC with operator-provided commands. Notable implementation details: the exploit requires valid credentials, uses curl for all HTTP interactions, relies on simple grep/sed/awk parsing rather than a JSON parser, and hardcodes a vulnerable version list of 1.10.10-1.11.3 even though the README broadly states <= 1.11.3. The script is operational rather than weaponized: it provides real exploitation capability, but payload customization is manual via the -c argument and there is no modular framework support.
This repository is a small standalone exploit repo for CVE-2025-54123 affecting HoverFly. It contains two files: a README describing the vulnerability and attack flow, and a Python exploit script (exploit.py) that operationalizes the attack. The exploit is not part of a larger framework. The Python script uses the requests library to authenticate to a HoverFly instance via /api/token-auth or accept a user-supplied bearer token, validate access to /api/v2/hoverfly/middleware, and then send a crafted PUT request to that endpoint. The malicious JSON payload abuses the vulnerable middleware validation logic by supplying a user-controlled binary and script. In practice, the exploit defaults to /bin/bash as the binary and places either a direct command or a base64-wrapped command into the script field. The script expects successful code execution to surface in a 422 response body and parses STDOUT from the returned error text. Capabilities exposed by the exploit include: authenticated single-command execution, an interactive pseudo-shell loop that repeatedly submits commands, and reverse shell triggering using a bash /dev/tcp payload to an attacker-controlled LHOST:LPORT. The exploit includes session validation, command output parsing, timeout handling for reverse shell delivery, and optional disabling of base64 wrapping. Fingerprintable targets/endpoints in the code are limited and directly tied to the exploit flow: /api/token-auth for login, /api/v2/hoverfly/middleware for vulnerability reachability testing and exploitation, /bin/bash as the execution binary, and the bash reverse shell pattern using /dev/tcp/LHOST/LPORT. Overall, this is a real authenticated RCE exploit with practical post-auth command execution functionality rather than a detection-only script or a fake proof of concept.
This repository is a small standalone exploit repo containing one Python exploit script and one README. The main file, CVE-2025-54123.py, is a command-line authenticated RCE exploit targeting Hoverfly <= 1.11.3. It is not part of a larger exploitation framework. Repository structure: - CVE-2025-54123.py: primary exploit implementation. - README.md: vulnerability description, usage examples, attack flow, impact, and references. Exploit workflow: 1. Accepts target URL, username, password, command, and optional shell path from the command line. 2. Authenticates to the Hoverfly Admin API using POST /api/token-auth with JSON credentials. 3. Stores the returned token and uses it as a Bearer token in subsequent requests. 4. Builds a malicious JSON payload with attacker-controlled fields: binary (shell path) and script (command string). 5. Sends the payload via PUT to /api/v2/hoverfly/middleware. 6. Parses the HTTP response for an error field containing a STDOUT section and prints extracted command output. Main exploit capabilities: - Authenticated arbitrary command execution on the target Hoverfly host. - Operator-controlled shell selection, defaulting to /bin/bash. - Output recovery from server responses, making it useful for interactive validation and post-exploitation reconnaissance. - Supports arbitrary commands, including file reads and reverse shell one-liners, though no automated staging or persistence logic is built in. Technical observations: - Uses only Python standard library modules (argparse, json, urllib, sys). - No concurrency, obfuscation, persistence, or framework integration. - The exploit is operational rather than a mere proof-of-concept because it performs end-to-end authentication, exploit delivery, and output extraction. - The README claims Basic Auth in one section, but the actual code uses token-based authentication via /api/token-auth and Authorization: Bearer <token>. Overall purpose: The repository is designed to provide a direct, operator-driven exploit for authenticated command injection in Hoverfly middleware configuration. Its purpose is to demonstrate and weaponize the vulnerable middleware execution path by turning valid admin API access into remote code execution.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-54123 affecting Hoverfly versions 1.11.3 and earlier. It contains only two files: a README with usage instructions and a single executable Python script, cve-2025-54123.py, which is the main exploit entry point. The exploit accepts five arguments: target host, target port, attacker host, attacker port, and a Bearer token. It constructs an HTTP URL to the Hoverfly API endpoint /api/v2/hoverfly/middleware and sends an authenticated PUT request with JSON data. The JSON body sets the middleware binary to /bin/sh and injects a shell command that creates a FIFO at /tmp/f and launches a netcat-based reverse shell back to the attacker listener at the supplied lhost:lport. Operationally, this is an authenticated network/web RCE exploit rather than a scanner or detector. It does not verify vulnerability conditions beyond issuing the request and printing the returned HTTP status code. The exploit’s main capability is remote code execution through malicious middleware configuration, with the intended post-exploitation outcome being an interactive reverse shell. Because the reverse shell command is hardcoded but parameterized for callback host and port, the repository is best classified as OPERATIONAL rather than a simple POC. Notable fingerprintable artifacts include the target API endpoint http://<rhost>:<rport>/api/v2/hoverfly/middleware, the Authorization: Bearer <token> header requirement, the use of /bin/sh and /tmp/f on the victim, and the outbound callback to the attacker-controlled listener over TCP using netcat.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.